fix(client): prevent URL corruption when replaceUrlParam contains $ replacement tokens - #5227
Merged
yusukebe merged 2 commits intoAug 16, 2026
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5227 +/- ##
=======================================
Coverage 79.77% 79.77%
=======================================
Files 155 155
Lines 10934 10934
Branches 2292 2292
=======================================
Hits 8723 8723
Misses 2211 2211 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Contributor
Author
|
@yusukebe sir , please look into this PR. |
Member
|
Don't hurry me. I'll review this later. |
Member
|
@adityajha77 Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix: Prevent
replaceUrlParamURL corruption on$replacement tokens in RPC & SSGSummary
Fixes a bug in
replaceUrlParam(src/client/utils.ts) where route parameter values containing$characters (e.g.$100,item$&,test$\``,test$') trigger JavaScript's string replacement token parser. This corrupts generated URLs in both the Hono RPC Client (hc) and the Static Site Generation (ssg) helper, leading to unexpected404 Not Found` errors.Root Cause Analysis
In
replaceUrlParam, parameter values were passed directly as a replacement string toString.prototype.replace():When the second argument is a raw string, JavaScript evaluates special replacement patterns inside
v:$&: Inserts the matched parameter token (e.g.:id), expanding/items/:idinto/items/item/:id.$1/$2: Inserts capture groups, turning$100into$00or00.$': Inserts the string segment following the match, duplicating trailing path segments.🛠️ Solution
Pass a replacer function
() => ...as the second argument toString.prototype.replace(). According to the ECMAScript specification, replacer functions bypass string replacement token parsing and treat the returned value as a literal string.Reproduction / Test Coverage
Added unit tests covering
$,$&,$1,$\``, and$'insrc/client/utils.test.ts`:Checklist
$character replacement handling insrc/client/utils.test.ts.replaceUrlParamunit tests pass, including regex parameters, optional parameters, and prefix matches.npm test.